Skip to main content
INELab Showcase
Back to CTF
P

pix3latedpic

@pix3latedpic
Resolving local date…
Maldives
hardware hacking and little bit of pentesting
Global rank
#2
All-time leaderboard
Total points
11,700
Across CTF seasons
Challenges solved
5
Distinct arenas
Captures solved
26
2796h 55m total
Activity

Submission rhythm.

Monthly Captures
01
Submissions

Public captures.

NexaCorp: Zero Credentials
You walk through a door using an identity you forgedCompleted450 pts
NexaCorp: Zero Credentials
The server fetches something internal on your behalfCompleted450 pts
NexaCorp: Zero Credentials
You gave yourself access the system never intended to grantCompleted450 pts
NexaCorp: Zero Credentials
A credential meant for someone else ends up in your handsCompleted450 pts
NexaCorp: Zero Credentials
Something was left exposed that shouldn't be publicCompleted450 pts
VulnCorp
What is the flag from the secrets vault accessed by exploiting the fail-open authentication bypass?Completed450 pts
VulnCorp
What is the flag returned by the exfiltration callback endpoint of the backdoored supply chain package?Completed450 pts
VulnCorp
What is the flag extracted from the AI assistant's internal configuration through prompt injection?Completed450 pts
VulnCorp
What is the flag retrieved from the internal cloud metadata service accessed via Server-Side Request Forgery?Completed450 pts
VulnCorp
What is the flag received after verifying the admin credentials obtained through SQL injection and password hash cracking?Completed450 pts
VulnCorp
What is the flag obtained from the debug admin panel accessed through secrets leaked in the exposed git commit history?Completed450 pts
Droid-Warden
If you’ve made it through the last door, it’s time to search for the treasure hidden within.Completed450 pts
Droid-Warden
Broken authentication is an invitation to attackers to walk right in. You don’t need to break the front door, it’s already unlocked.Completed450 pts
Droid-Warden
Feeling unwell? A doctor uses an injection. Some systems react similarly when prodded the right way.Completed450 pts
Droid-Warden
User “daniel” seems innocent enough, but not everyone takes security seriously, and he’s no exception.Completed450 pts
Droid-Warden
Look beyond what the app shows you to uncover the first flag.Completed450 pts
TravelEndpoint
Data is only as secure as its weakest link. Can you uncover information that shouldn't be accessible?Completed450 pts
TravelEndpoint
A system's curiosity can sometimes lead it to unexpected places. Can you make it fetch something valuable?Completed450 pts
TravelEndpoint
Certain reports are meant for specific eyes only. Can you access what's not meant for you?Completed450 pts
TravelEndpoint
Sometimes, what you send isn't what's saved. Can you manipulate the system to reveal what's hidden?Completed450 pts